Authentication vulnerability in Indeed Membership Pro 8.6.1

The Ultimate Membership Pro plugin for WordPress is vulnerable to a type of security breach called Authentication Bypass. This vulnerability exists in versions of the plugin from 7.3 to 8.6. It allows attackers who have not been properly authenticated to log in as any user, including the site administrator, without needing their username or password. The default user ID for the site administrator is 1.

Detected in:

Indeed Membership Pro fixed vulnerable versions: >= 7.3 < 8.6.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.